- Apr 3, 2009
- 591
- 320
The Japanese keyword hack is having a moment. Reports this week have a fresh wave chewing through WordPress sites and walking straight past WordFence, Sucuri and Malcare. Plugin says clean, site is not.
Quick anatomy for anyone who has not met it: the hack generates pages of autogenerated Japanese text in random directories on your domain, things like yoursite.com/ltjmnjp/341.html, stuffed with affiliate links to counterfeit goods. The pages are cloaked -> you click one and get a 404, Googlebot gets a live page. So browsing your own site tells you nothing.
Three checks that actually catch it:
If you are hit, order matters. Kick the rogue owner out first and delete their verification token, or they walk back in after your cleanup. Then a clean .htaccess, reinstall CMS core, and grep the codebase for base64_decode and eval before you trust anything. All of this is sitting in Google's own hacked-site doc, it just gets ignored because everyone assumes the plugin has the door covered.
Anyone eaten this wave in the last couple of weeks? Curious what caught it first for you: the plugin, a GSC message, or a customer asking why you sell Gucci now.
Quick anatomy for anyone who has not met it: the hack generates pages of autogenerated Japanese text in random directories on your domain, things like yoursite.com/ltjmnjp/341.html, stuffed with affiliate links to counterfeit goods. The pages are cloaked -> you click one and get a 404, Googlebot gets a live page. So browsing your own site tells you nothing.
Three checks that actually catch it:
- Search Console -> Users and permissions. This hack verifies ITSELF as an owner of your property, usually via a dropped verification file or an .htaccess rewrite. An owner you do not recognize is the loudest tell there is, and no security plugin is watching that page for you.
- site:yourdomain.com, scan for Japanese titles. Nothing on Google? Run the same search on Bing, Google sometimes drops the junk pages before you get around to looking.
- URL Inspection on any suspicious path. 404 in your browser but real content in the render = you are hit.
If you are hit, order matters. Kick the rogue owner out first and delete their verification token, or they walk back in after your cleanup. Then a clean .htaccess, reinstall CMS core, and grep the codebase for base64_decode and eval before you trust anything. All of this is sitting in Google's own hacked-site doc, it just gets ignored because everyone assumes the plugin has the door covered.
Anyone eaten this wave in the last couple of weeks? Curious what caught it first for you: the plugin, a GSC message, or a customer asking why you sell Gucci now.